It's a familiar experience: racing against masses of anonymous netizens online to get yourself on the list for an in-demand event.
For Andrew Bird, from Melbourne, in Australia, it was a spot in an often over-booked pilates class - but his solution had unexpected consequences.
He says he outsourced the "chore" to an AI agent - a tool that can carry out online tasks autonomously.
It succeeded, but went further than he imagined by hacking the gym's online systems, in what is being seen as the latest example of the way AI agents will go to any lengths to carry out the jobs they've been given.
"What made the whole thing more surreal was the tone," Bird wrote in his blog.
"The bot was not malicious. It was helpful."
The news comes as AI firms have been admitting in recent weeks that their AI bots have been going on uncontrollable hacking sprees in testing sessions gone wrong.
OpenAI, Anthropic and Meta have all revealed that their own AI bots have carried out cyber-attacks on private companies in the pursuit of goals set by their makers.
The gym booking incident is not considered a serious cyber-attack but is another example of the unintended consequences of tasking sophisticated AI bots with jobs.
It actually happened in April, but has come to light now thanks to reporting from ABC News Australia, external.
Bird declined to talk to the BBC about it saying only: "Thanks for getting in touch. I am unavailable to participate in an interview. Appreciate your interest the story."
He has also deleted his blog post about it from the time - but not explained why.
According to his account, Bird was using the software OpenClaw - a popular tool that allows users to chat to their AI bots (in this case Athropic's Claude Opus 4.6) through WhatsApp and set it off on autonomous tasks.
He had previously used it to manage his emails, calendar and book restaurants.
Once given the gym booking task, the bot explained that it had manipulated the system to book him onto classes months in advance - against the normal rules of the system.
The AI technologist then wondered if the agent could move him up the waiting list for an upcoming class.
The agent replied saying it had succeeded by cancelling another gym-goer's booking.
According to the ABC News report the AI bot told Bird: "The API has zero authorisations checks on cancelling other people's reservations … I tested this with the person in waitlist position #1 — and it actually went through. So you've moved from #4 to #3 already."
Bird asked the bot to reverse the action but it wasn't able to so he asked it to write a cyber-security report and alert the gym owners about the vulnerability.
Bird, who runs an AI document making company, says he had no intention of cancelling his fellow pilates fan's spot.
"It's not the end of the world, so I didn't beat myself up about it, but it certainly was a warning signal to use it responsibly," he told ABC News.

1 hour ago
1









